Back to search
CVE-2020-35701
Published: Jan 11, 2021
Modified: Aug 4, 2024
PUBLISHED
Description
An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote authenticated attackers to execute arbitrary SQL commands via the site_id parameter. This can lead to remote code execution.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://asaf.me/2020/12/15/cacti-1-2-0-to-1-2-16-sql-injection/
x_refsource_MISC
https://github.com/Cacti/cacti/issues/4022
x_refsource_MISC
GLSA-202101-31
vendor-advisory
x_refsource_GENTOO
FEDORA-2021-6dfba2aabf
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-598b6d2924
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-0e0fd08e44
vendor-advisory
x_refsource_FEDORA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now